1. 在web.xml里加上:
<security-constraint>
<web-resource-collection>
<web-resource-name>HTMLManger and Manager command</web-resource-name>
//a.doc和ccc.txt是需要登录才能查看或下载的文件
<url-pattern>/a.doc</url-pattern>
<url-pattern>/ccc.txt</url-pattern>
<http-method>GET</http-method>
<http-method>POST</http-method>
</web-resource-collection>
<auth-constraint>
<!-- NOTE: This role is not present in the default users file -->
<role-name>manager</role-name> //这个组的成员用户登录后可以下载上述文件
</auth-constraint>
</security-constraint>
<login-config>
<auth-method>BASIC</auth-method>
<realm-name></realm-name>
</login-config>
<security-role>
<description>The role that is required to log in to the Manager Application</description>
<role-name>manager</role-name> //这个组的成员用户登录后可以下载上述文件
</security-role>